ID

VAR-201311-0287


CVE

CVE-2013-5215


TITLE

FOSCAM Wireless IP Camera Cross-Site Scripting Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2013-14396 // CNNVD: CNNVD-201311-094

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID. The FOSCAM Wireless IP Camera is a wireless IP camera. FOSCAM Wireless IP Camera is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 2.52

sources: NVD: CVE-2013-5215 // JVNDB: JVNDB-2013-005206 // CNVD: CNVD-2013-14396 // BID: 63583 // VULHUB: VHN-65217

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14396

AFFECTED PRODUCTS

vendor:foscammodel:wireless ip camerascope:eqversion: -

Trust: 1.6

vendor:foscam intelligentmodel:wireless ip camerascope: - version: -

Trust: 0.8

vendor: - model:foscam intelligent technology limited copyright. foscam wireless ip camerascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2013-14396 // JVNDB: JVNDB-2013-005206 // CNNVD: CNNVD-201311-094 // NVD: CVE-2013-5215

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5215
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-5215
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-14396
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201311-094
value: MEDIUM

Trust: 0.6

VULHUB: VHN-65217
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-5215
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-14396
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-65217
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-14396 // VULHUB: VHN-65217 // JVNDB: JVNDB-2013-005206 // CNNVD: CNNVD-201311-094 // NVD: CVE-2013-5215

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-65217 // JVNDB: JVNDB-2013-005206 // NVD: CVE-2013-5215

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201311-094

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201311-094

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-005206

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-65217

PATCH

title:Top Pageurl:http://www.foscam.com/

Trust: 0.8

sources: JVNDB: JVNDB-2013-005206

EXTERNAL IDS

db:NVDid:CVE-2013-5215

Trust: 3.4

db:SECUNIAid:55080

Trust: 1.7

db:OSVDBid:99550

Trust: 1.7

db:PACKETSTORMid:123943

Trust: 1.7

db:BIDid:63583

Trust: 1.6

db:JVNDBid:JVNDB-2013-005206

Trust: 0.8

db:CNNVDid:CNNVD-201311-094

Trust: 0.7

db:CNVDid:CNVD-2013-14396

Trust: 0.6

db:XFid:20135215

Trust: 0.6

db:XFid:88629

Trust: 0.6

db:FULLDISCid:20131107 FOSCAM WIRELESS IP CAMERA - SSID CROSS SITE SCRIPTING

Trust: 0.6

db:VULHUBid:VHN-65217

Trust: 0.1

sources: CNVD: CNVD-2013-14396 // VULHUB: VHN-65217 // BID: 63583 // JVNDB: JVNDB-2013-005206 // CNNVD: CNNVD-201311-094 // NVD: CVE-2013-5215

REFERENCES

url:http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0046.html

Trust: 2.5

url:http://packetstormsecurity.com/files/123943/foscam-wireless-ip-camera-cross-site-scripting.html

Trust: 1.7

url:http://osvdb.org/99550

Trust: 1.7

url:http://secunia.com/advisories/55080

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/88629

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5215

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5215

Trust: 0.8

url:http://seclists.org/fulldisclosure/2013/nov/49

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/88629

Trust: 0.6

url:http://www.securityfocus.com/bid/63583

Trust: 0.6

sources: CNVD: CNVD-2013-14396 // VULHUB: VHN-65217 // JVNDB: JVNDB-2013-005206 // CNNVD: CNNVD-201311-094 // NVD: CVE-2013-5215

CREDITS

Liad Mizrachi

Trust: 0.9

sources: BID: 63583 // CNNVD: CNNVD-201311-094

SOURCES

db:CNVDid:CNVD-2013-14396
db:VULHUBid:VHN-65217
db:BIDid:63583
db:JVNDBid:JVNDB-2013-005206
db:CNNVDid:CNNVD-201311-094
db:NVDid:CVE-2013-5215

LAST UPDATE DATE

2025-04-11T23:17:15.092000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14396date:2013-11-12T00:00:00
db:VULHUBid:VHN-65217date:2017-08-29T00:00:00
db:BIDid:63583date:2013-11-07T00:00:00
db:JVNDBid:JVNDB-2013-005206date:2013-11-21T00:00:00
db:CNNVDid:CNNVD-201311-094date:2013-11-22T00:00:00
db:NVDid:CVE-2013-5215date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-14396date:2013-11-12T00:00:00
db:VULHUBid:VHN-65217date:2013-11-20T00:00:00
db:BIDid:63583date:2013-11-07T00:00:00
db:JVNDBid:JVNDB-2013-005206date:2013-11-21T00:00:00
db:CNNVDid:CNNVD-201311-094date:2013-11-08T00:00:00
db:NVDid:CVE-2013-5215date:2013-11-20T13:19:42.350